#VU112001 Buffer overflow in fig2dev - CVE-2020-21683
Published: June 27, 2025
fig2dev
mcj
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error within the shade_or_tint_name_after_declare_color() function in fig2dev/dev/genpstricks.c when converting a xfig file into pstricks format. A remote attacker can pass a specially crafted file to the application and crash it.